mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 08:03:15 +00:00
docs(migration): record the two Bedrock IAM users + scoped invoke policy (#74)
Document the live execution of MIGRATION.md §10.1 (Bedrock auth via static keys): the customer-managed least-privilege policy open-swe-bedrock-invoke and the open-swe-dev-bedrock / open-swe-prod-bedrock IAM users. Captures the static-key deviation rationale (managed LangGraph Cloud cannot assume a role) and that both mandatory gates (GPT-4.1 IAM cross-review, /sh-security-review) passed with no critical/high.
This commit is contained in:
parent
49fd48d32f
commit
8441bbb2d8
1 changed files with 12 additions and 0 deletions
|
|
@ -177,6 +177,18 @@ Post-#62 `SUPPORTED_MODELS` = `bedrock_converse:us.anthropic.claude-opus-4-8` (*
|
||||||
- (a) Static `AWS_ACCESS_KEY_ID` / `AWS_SECRET_ACCESS_KEY` / `AWS_REGION` for a **Bedrock-scoped IAM user** in the deployment env, or
|
- (a) Static `AWS_ACCESS_KEY_ID` / `AWS_SECRET_ACCESS_KEY` / `AWS_REGION` for a **Bedrock-scoped IAM user** in the deployment env, or
|
||||||
- (b) Run the agent on **Fireworks** and avoid Bedrock entirely on managed.
|
- (b) Run the agent on **Fireworks** and avoid Bedrock entirely on managed.
|
||||||
|
|
||||||
|
### Bedrock IAM users (CREATED — resolves §10.1, discharges the §9 IAM gates)
|
||||||
|
Option (a) was chosen and executed live (2026-06-30, account **328440206208** / **us-east-1**). This is **click-ops IAM** — there is no remaining open-swe AWS IaC after the decommission (#64), so these are created with the CLI, not CDK.
|
||||||
|
|
||||||
|
- **Customer-managed policy `open-swe-bedrock-invoke`** (`arn:aws:iam::328440206208:policy/open-swe-bedrock-invoke`). Least-privilege: actions `bedrock:InvokeModel` + `bedrock:InvokeModelWithResponseStream` **only**, scoped to exactly the `us.anthropic.claude-opus-4-8` inference-profile ARN + its **three** routed foundation-model ARNs (us-east-1, us-east-2, us-west-2). **No wildcards, no other models.** (Supersedes the §10.1 plan to reuse the #62 instance-role policy — a fresh standalone policy was minted instead.)
|
||||||
|
- **Two IAM users**, each attached to that policy: **`open-swe-dev-bedrock`** and **`open-swe-prod-bedrock`**. Tagged `project=open-swe`, `managed-by=cli-migration`, `purpose=bedrock-invoke`.
|
||||||
|
- **Static access keys are minted separately by the owner** (`aws iam create-access-key`) — secret keys live **only** in the deployment env stores, never in this repo or memory. dev key → dev env; prod key → LangGraph Cloud prod config (`AWS_ACCESS_KEY_ID` / `AWS_SECRET_ACCESS_KEY` / `AWS_REGION=us-east-1`).
|
||||||
|
- **Deviation rationale:** static long-lived keys are a deliberate departure from the Sea Haven OIDC norm because **managed LangGraph Cloud cannot assume an AWS role**. Mitigated by the tight least-privilege policy above.
|
||||||
|
- ✅ **Both mandatory gates ran and PASSED:**
|
||||||
|
- **GPT-4.1 IAM cross-review** (confirmed hit `gpt-4.1-2025-04-14`) — least-privilege confirmed.
|
||||||
|
- **`/sh-security-review`** — **0 critical/high**; two **accepted mediums** (the static-key deviation + no per-principal budget cap).
|
||||||
|
- **Recommended follow-ups:** shortest viable key-rotation cadence with recorded creation dates; an AWS Budgets / CloudWatch anomaly alarm on per-principal Bedrock `InvokeModel` volume; confirm CloudTrail captures these users.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## 5. Required Code Fixes (the 6 gotchas)
|
## 5. Required Code Fixes (the 6 gotchas)
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue